Browser Session Incident Response Guide

Use this sequence when a browser, endpoint, or web session may be compromised. Adapt it to your incident-response plan, evidence requirements, and provider capabilities.

See Strong Single Logout
warning

Treat browser containment as one part of the response.

Clearing local cookies and site storage can remove access from that browser profile. It cannot recall a token already copied elsewhere or invalidate every provider-side session. Preserve required evidence and use endpoint, identity, and application controls together.

1

Triage and preserve evidence

  • Record who reported the event, affected employee, device, browser profile, time range, and observed behavior.
  • Determine whether the user, endpoint, identity, or a specific application appears compromised.
  • Preserve volatile or forensic evidence required by your response plan before clearing data or restarting systems.
  • Identify sensitive applications already open in the browser and privileged accounts the person can reach.
2

Contain the endpoint and browser

  • Isolate the endpoint with your EDR, MDM, or network controls when the threat calls for it.
  • Use Strong Single Logout in Locke Armory to clear cookies and site storage from connected Locke browser profiles and revoke Locke sessions.
  • Account for other browser profiles, unmanaged browsers, mobile apps, and devices without an authenticated Locke extension.
  • Do not destroy evidence or wipe devices unless your approved incident process calls for it.
3

Revoke identity and application sessions

  • Disable or restrict the identity if continued authentication creates risk.
  • Revoke identity-provider refresh tokens and active sessions using the provider's emergency controls.
  • Revoke sessions directly in sensitive SaaS applications, especially tools outside SSO or automated provisioning.
  • Remove suspicious OAuth grants, app passwords, API tokens, remembered devices, and recovery methods.
4

Rotate credentials and investigate

  • Reset affected passwords and rotate exposed shared credentials, API keys, secrets, and recovery codes.
  • Review identity, endpoint, email, SaaS, and network logs for session creation, unusual access, downloads, persistence, and lateral movement.
  • Determine the initial access path and whether the same session material or credentials reached another device.
  • Expand containment to other identities or systems based on evidence—not assumption.
5

Recover, verify, and monitor

  • Remediate or rebuild the endpoint according to your security standard before restoring access.
  • Re-enable access only after credentials, authenticators, browser extensions, and device trust are in a known-good state.
  • Verify session revocation in critical providers and monitor for reauthentication or repeated indicators.
  • Document decisions, actions, evidence, residual risks, and follow-up owners in the incident record.

Incident notes